Security experts have reported that a significant Adobe Commerce vulnerability was exploited by hackers immediately following its public announcement. According to Sansec, a webstore security company, the flaw was targeted right after its disclosure.
Details of the Security Flaw
The vulnerability, identified as CVE-2026-71362, carries a CVSS score of 9.1, indicating its critical nature. It involves incorrect authorization, which can grant unauthorized attackers the ability to elevate their access privileges.
Adobe addressed this issue during the August 2026 Patch Tuesday. Initially, they had no evidence of the flaw being actively exploited, though they cautioned that Commerce has been targeted previously.
Immediate Exploitation Post-Disclosure
Shortly after Adobe issued their advisory, Sansec observed the first attempts to exploit the CVE. The vulnerability can be leveraged by remote, unauthenticated attackers to compromise customer accounts.
Sansec confirmed that exploiting the flaw enables attackers to hijack a customer session, allowing unauthorized access to another user’s account and sensitive data.
Patch and Recommendations
Adobe has resolved the issue by modifying the way Commerce and Magento manage customer identities during account sessions. The vulnerability affects all versions of Commerce, Commerce B2B, and Magento Open Source up to and including those with July 2026 updates.
On a recent Tuesday, Adobe released a specialized patch to rectify this critical flaw, along with fixes for six other security issues across their products. They also provided detailed installation instructions.
Adobe emphasizes the importance of applying these security updates promptly, as successful exploitation could lead to arbitrary code execution, bypassing security features, and privilege escalation.
The isolated patch enables merchants to implement the fix with minimal risk of delays caused by integration issues.
For further reading, similar security updates were applied to WordPress, Zoom, and SonicWall, highlighting the ongoing need for vigilance in cybersecurity practices.
